7.1

CVSS4.0

CVE-2025-15239 - Quanta Computer|QOCA aim AI Medical Cloud Platform - SQL Injection

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Jan. 5, 2026, 8:10 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:09 p.m.

5.3

CVSS4.0

CVE-2026-0581 - Tenda AC1206 httpd BehaviorManager formBehaviorManager command injection

A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command injection. The attack can be …

📅 Published: Jan. 5, 2026, 8:02 a.m. 🔄 Last Modified: April 18, 2026, 8:30 a.m.

7.1

CVSS4.0

CVE-2025-15238 - Quanta Computer|QOCA aim AI Medical Cloud Platform - SQL Injection

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.

📅 Published: Jan. 5, 2026, 8 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:09 p.m.

4.8

CVSS4.0

CVE-2025-15022 - Cross-site scripting in Action caption

Action captions in Vaadin accept HTML by default but were not sanitized, potentially allowing Cross-site Scripting (XSS) if caption content is derived from user input. In Vaadin Framework 7 and 8, the Action class is a general-purpose class that may be used by multiple components. The fixed versio…

📅 Published: Jan. 5, 2026, 7:52 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-15237 - Quanta Computer|QOCA aim AI Medical Cloud Platform - Path Traversal

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.

📅 Published: Jan. 5, 2026, 7:42 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:14 p.m.

5.3

CVSS4.0

CVE-2025-15236 - Quanta Computer|QOCA aim AI Medical Cloud Platform - Path Traversal

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.

📅 Published: Jan. 5, 2026, 7:38 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:15 p.m.

5.1

CVSS4.0

CVE-2026-0580 - SourceCodester API Key Manager App Import Key cross site scripting

A vulnerability was found in SourceCodester API Key Manager App 1.0. Affected by this vulnerability is an unknown functionality of the component Import Key Handler. Performing a manipulation results in cross site scripting. The attack can be initiated remotely.

📅 Published: Jan. 5, 2026, 7:32 a.m. 🔄 Last Modified: April 18, 2026, 8:30 a.m.

7.1

CVSS4.0

CVE-2025-15235 - Quanta Computer|QOCA aim AI Medical Cloud Platform - Missing Authorization

QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Missing Authorization vulnerability, allowing authenticated remote attackers to modify specific network packet parameters, enabling certain system functions to access other users' files.

📅 Published: Jan. 5, 2026, 7:25 a.m. 🔄 Last Modified: Jan. 20, 2026, 9:12 p.m.

8.7

CVSS4.0

CVE-2025-15462 - UTT 进取 520W ConfigAdvideo strcpy buffer overflow

A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public …

📅 Published: Jan. 5, 2026, 7:02 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:18 a.m.

8.7

CVSS4.0

CVE-2025-15461 - UTT 进取 520W formTaskEdit strcpy buffer overflow

A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTaskEdit. Executing a manipulation of the argument selDateType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. …

📅 Published: Jan. 5, 2026, 6:32 a.m. 🔄 Last Modified: Feb. 23, 2026, 8:18 a.m.
Total resulsts: 347394
Page 2113 of 34,740
« previous page » next page
Filters